Ally was carrying an SQL injection flaw that allowed data exfiltration.
A vulnerability in the Ally WordPress plugin exposes over 200,000 websites to sensitive information disclosure via SQL queries.